Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
json vulnerabilities and exploits
(subscribe to this query)
516
VMScore
CVE-2020-10594
An issue exists in drf-jwt 1.15.x prior to 1.15.1. It allows attackers with access to a notionally invalidated token to obtain a new, working token via the refresh endpoint, because the blacklist protection mechanism is incompatible with the token-refresh feature. NOTE: drf-jwt i...
Styria Django-rest-framework-json Web Tokens
NA
CVE-2022-4666
The Markup (JSON-LD) structured in schema.org WordPress plugin up to and including 4.8.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and ab...
Terakoya Markup \\(json-ld\\) Structured In Schema.org
578
VMScore
CVE-2019-3683
The keystone-json-assignment package in SUSE Openstack Cloud 8 before commit d7888c75505465490250c00cc0ef4bb1af662f9f every user listed in the /etc/keystone/user-project-map.json was assigned full "member" role access to every project. This allowed these users to access...
Suse Openstack Cloud 8.0
Suse Keystone-json-assignment
Hp Helion Openstack 8.0
447
VMScore
CVE-2020-10663
The JSON gem up to and including 2.2.0 for Ruby, as used in Ruby 2.4 up to and including 2.4.9, 2.5 up to and including 2.5.7, and 2.6 up to and including 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage...
Json Project Json
Fedoraproject Fedora 30
Fedoraproject Fedora 31
Opensuse Leap 15.1
Debian Debian Linux 8.0
Debian Debian Linux 10.0
Apple Macos 11.0.1
8 Github repositories
605
VMScore
CVE-2020-12762
json-c up to and including 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
Json-c Json-c
Fedoraproject Fedora 30
Fedoraproject Fedora 31
Fedoraproject Fedora 32
Debian Debian Linux 8.0
Debian Debian Linux 9.0
Debian Debian Linux 10.0
Canonical Ubuntu Linux 18.04
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 19.10
Canonical Ubuntu Linux 20.04
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 12.04
Siemens Sinec Ins 1.0
Siemens Sinec Ins -
578
VMScore
CVE-2020-7712
This affects the package json prior to 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
Joyent Json
Oracle Commerce Guided Search 11.3.2
Oracle Timesten In-memory Database
Oracle Financial Services Regulatory Reporting With Agilereporter 8.0.9.6.3
Oracle Financial Services Crime And Compliance Management Studio 8.0.8.2.0
Oracle Financial Services Crime And Compliance Management Studio 8.0.8.3.0
668
VMScore
CVE-2019-11834
cJSON prior to 1.7.11 allows out-of-bounds access, related to \x00 in a string literal.
Cjson Project Cjson
Oracle Timesten In-memory Database
668
VMScore
CVE-2019-11835
cJSON prior to 1.7.11 allows out-of-bounds access, related to multiline comments.
Cjson Project Cjson
Oracle Timesten In-memory Database
668
VMScore
CVE-2016-4303
The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote malicious users to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer overflow.
Iperf3 Project Iperf3
Novell Suse Package Hub For Suse Linux Enterprise 12
Opensuse Leap 42.1
Opensuse Opensuse 13.2
Debian Debian Linux 8.0
668
VMScore
CVE-2018-21234
Jodd prior to 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.
Jodd Jodd
Apache Hive 3.1.2
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
2
3
4
5
6
7
8
9
10
NEXT »